ASHRM Certified Professional in Healthcare Risk Management (CPHRM) Exam — Questions and Answers
Question 1: Under a retrospective rating plan, the final premium is determined by:
- Projected losses set at policy inception
- Actual losses during the policy period, subject to minimum and maximum limits (Correct answer)
- A fixed percentage of payroll regardless of claims
- The insurer's discretion at policy renewal
Correct answer: Actual losses during the policy period, subject to minimum and maximum limits
Retrospective rating adjusts the final premium based on the insured's actual loss experience during the policy period, bounded by a contractual minimum and maximum.
Question 2: A risk manager reviews an actuarial loss reserve study. The actuary uses an 'ultimate loss' estimate rather than paid losses. Why is ultimate loss the more appropriate figure for funding decisions?
- It excludes defense costs to provide a cleaner liability estimate
- It is always smaller than paid losses, reducing reserve requirements
- It includes both paid amounts and estimated future payments on open and IBNR claims (Correct answer)
- It uses only the most recent three years of data to minimize volatility
Correct answer: It includes both paid amounts and estimated future payments on open and IBNR claims
Ultimate loss includes paid amounts, case reserves on open claims, and incurred-but-not-reported (IBNR) estimates, giving the full projected cost of all claims from a period.
Question 3: Which financial statement metric is MOST useful for a risk manager assessing whether a self-insured trust fund has adequate liquidity to pay near-term claims?
- Return on equity
- Debt-to-equity ratio
- Current ratio (Correct answer)
- Price-to-earnings ratio
Correct answer: Current ratio
The current ratio (current assets divided by current liabilities) measures short-term liquidity, indicating whether a fund has sufficient liquid assets to cover near-term claim payments.
Question 4: Which operational risk management tool helps healthcare organizations proactively identify failure points in a process before harm occurs?
- Failure Mode and Effects Analysis (FMEA) (Correct answer)
- Balance sheet review
- Post-incident litigation review
- Claims frequency analysis
Correct answer: Failure Mode and Effects Analysis (FMEA)
FMEA is a proactive method that systematically examines a process to identify where and how it might fail and the effects of those failures.
Question 5: A hospital switches from a claims-made policy to an occurrence policy. What does the hospital need to purchase to cover claims arising from incidents that occurred during the claims-made period but are reported after the switch?
- Umbrella coverage
- Nose coverage
- Excess liability coverage
- Tail coverage (extended reporting endorsement) (Correct answer)
Correct answer: Tail coverage (extended reporting endorsement)
Tail coverage (extended reporting endorsement) extends the reporting window of a claims-made policy to capture incidents that occurred during the policy period but are reported after it ends.
Question 6: Which professional attribute is most valued in risk identification within the CPHRM field?
- Prioritizing personal convenience
- Avoiding challenging situations
- Accountability and commitment to standards (Correct answer)
- Working in isolation
Correct answer: Accountability and commitment to standards
Accountability and commitment to professional standards build trust and ensure consistent, high-quality practice.
Question 7: Which element is NOT required to establish a medical malpractice claim?
- Intent to harm (Correct answer)
- Duty of care
- Causation
- Breach of the standard of care
Correct answer: Intent to harm
Medical malpractice is a negligence-based claim requiring duty, breach, causation, and damages — intent to harm is not an element of negligence.
Question 8: Which of the following BEST describes 'sensitivity analysis' in the context of quantitative risk assessment?
- Assessing patient sensitivity to medications as a risk factor
- Testing how changes in input variables affect the overall risk model output (Correct answer)
- Measuring the detection threshold of control systems
- Evaluating staff sensitivity to workplace safety concerns
Correct answer: Testing how changes in input variables affect the overall risk model output
Sensitivity analysis varies individual input parameters to determine which variables have the greatest influence on the risk model's results.
Question 9: In healthcare risk analysis, 'inherent risk' is BEST defined as:
- Risk that is embedded in the organization's culture
- Risk accepted as part of normal clinical practice
- Risk that cannot be eliminated regardless of controls
- The level of risk that exists before any controls are applied (Correct answer)
Correct answer: The level of risk that exists before any controls are applied
Inherent risk is the raw or baseline risk of an activity or process before any mitigation or control measures are considered.
Question 10: Lean methodology in healthcare quality improvement primarily aims to:
- Eliminate waste and improve efficiency in care delivery processes (Correct answer)
- Increase staffing levels to reduce workload-related errors
- Standardize clinical decision-making through algorithmic guidelines
- Reduce statistical variation in clinical outcomes using data analysis
Correct answer: Eliminate waste and improve efficiency in care delivery processes
Lean focuses on identifying and eliminating waste (non-value-added activities) in processes to improve efficiency, flow, and quality.
Question 11: During a hospital survey, a surveyor asks staff to describe what they would do if they noticed a safety concern. This line of questioning MOST directly assesses:
- Equipment maintenance schedules
- Compliance with billing codes
- Staffing adequacy
- Safety culture and staff empowerment to speak up (Correct answer)
Correct answer: Safety culture and staff empowerment to speak up
Surveyors assess whether staff feel empowered and safe to report concerns without retaliation, which is a core indicator of patient safety culture.
Question 12: A risk manager reviewing medication error trends notices most errors occur during the transcription step. This represents which type of error source?
- Sentinel event
- Latent failure (Correct answer)
- Adverse drug reaction
- Active failure
Correct answer: Latent failure
Latent failures are organizational or system-level weaknesses—such as poor transcription processes—that lie dormant until triggered by human action.
Question 13: Which safety strategy involves double-checking a high-alert medication dose independently before administration?
- Bar-code medication administration
- Tall man lettering
- Independent double-check (Correct answer)
- Read-back verification
Correct answer: Independent double-check
Independent double-checks require two clinicians to separately verify a calculation or drug without conferring, reducing the chance of shared cognitive error.
Question 14: The legal doctrine of res ipsa loquitur allows a plaintiff to establish negligence without direct proof when:
- The plaintiff has filed a complaint with a licensing board
- The defendant is a licensed professional
- The injury would not ordinarily occur without negligence and the defendant had control (Correct answer)
- The hospital has admitted liability
Correct answer: The injury would not ordinarily occur without negligence and the defendant had control
Res ipsa loquitur applies when the injury speaks for itself — it wouldn't normally occur without negligence and the defendant controlled the instrumentality causing harm.
Question 15: The medicine system at a hospital is extensive, and different parts of it are under the jurisdiction of several departments. What is one crucial step that may be taken to lessen system errors?
- Simplify it
- Make each department responsible for the system as a whole
- Give a single person responsibility for overseeing the entire system (Correct answer)
- Have each department use the same self-assessment tools
Correct answer: Give a single person responsibility for overseeing the entire system
In complex systems involving multiple departments, a lack of centralized oversight can lead to fragmented processes, communication breakdowns, and increased errors. Appointing a single person with overall responsibility for the entire system ensures a holistic view, promotes coordination across departments, and facilitates consistent policy implementation and error prevention. This centralized accountability helps identify and address systemic vulnerabilities that might otherwise be missed when responsibilities are siloed.
Question 16: Under the False Claims Act, the 'qui tam' provision allows:
- Hospitals to self-disclose billing errors without penalty
- CMS to directly audit hospital billing records
- Private individuals to file lawsuits on behalf of the government and share in recovered damages (Correct answer)
- The OIG to impose mandatory exclusions without a hearing
Correct answer: Private individuals to file lawsuits on behalf of the government and share in recovered damages
The qui tam provision of the False Claims Act allows whistleblowers (relators) to file lawsuits on behalf of the government and receive 15-30% of recovered funds.
Question 17: Under the Emergency Medical Treatment and Labor Act (EMTALA), a hospital's primary obligation to any person presenting to the emergency department is to:
- Transfer the patient to a public hospital immediately
- Perform a medical screening examination and stabilize emergency conditions (Correct answer)
- Verify insurance before providing care
- Obtain informed consent before any evaluation
Correct answer: Perform a medical screening examination and stabilize emergency conditions
EMTALA requires hospitals to provide a medical screening exam and necessary stabilizing treatment regardless of ability to pay.
Question 18: A risk manager notices a pattern of patient falls in a specific unit during night shifts. This analysis technique is called:
- Trend analysis (Correct answer)
- Sentinel event review
- Root cause analysis
- Benchmarking
Correct answer: Trend analysis
Trend analysis identifies patterns in data over time to detect emerging risks before they escalate.
Question 19: A hospital's compliance program must include which element identified in the OIG's seven elements of an effective compliance program?
- A dedicated compliance department with at least 10 staff members
- Board-level approval of all compliance policies
- Mandatory external audits by an independent CPA firm
- Ongoing monitoring and auditing of compliance risks (Correct answer)
Correct answer: Ongoing monitoring and auditing of compliance risks
OIG's seven elements include: written standards, compliance officer/committee, training, communication channels, auditing/monitoring, disciplinary guidelines, and response to detected offenses — ongoing auditing and monitoring is one of the seven.
Question 20: The primary risk management concern with a hospital's non-compete agreements for employed physicians is:
- Potential HIPAA violations if patient lists are shared
- Violation of the Stark Law's compensation exception requirements
- Antitrust implications and interference with patient access to care (Correct answer)
- Non-compliance with medical staff bylaws
Correct answer: Antitrust implications and interference with patient access to care
Overly broad non-compete agreements for physicians raise antitrust concerns and can impair patient access to care, drawing FTC and state attorney general scrutiny.
Question 21: A hospital risk manager learns that a physician has been performing procedures without current privileges for that specific procedure. The FIRST action should be:
- Notify the state licensing board
- Immediately revoke the physician's medical license
- File a report with the National Practitioner Data Bank
- Suspend the physician's ability to perform that procedure and initiate a peer review (Correct answer)
Correct answer: Suspend the physician's ability to perform that procedure and initiate a peer review
The immediate priority is patient safety by stopping the unauthorized procedures, followed by a formal peer review process through the credentialing committee.
Question 22: A risk manager notices a pattern of falls in one unit after reviewing incident reports. What is the BEST next step?
- Immediately report to the board
- Transfer patients to other units
- Dismiss the pattern as statistical noise
- Conduct a focused process improvement initiative for that unit (Correct answer)
Correct answer: Conduct a focused process improvement initiative for that unit
Aggregated incident data indicating a unit-specific pattern should trigger a focused process improvement to address contributing factors.
Question 23: A risk manager is tasked with identifying risks in a newly implemented telemedicine program. The BEST initial approach is to:
- Review state licensure laws only
- Benchmark against internal in-person care metrics only
- Conduct a prospective risk assessment of the new workflow and technology (Correct answer)
- Wait for the first incident report before acting
Correct answer: Conduct a prospective risk assessment of the new workflow and technology
Prospective risk assessment of new programs identifies potential failure points before patients are exposed to harm.
Question 24: Which committee is MOST likely to provide risk managers with information about clinical risks related to physician performance?
- Compliance committee
- Medical executive committee (Correct answer)
- Facilities management committee
- Finance committee
Correct answer: Medical executive committee
The medical executive committee oversees physician credentialing, peer review, and performance issues that directly relate to clinical risk.
Question 25: The primary purpose of a Healthcare Failure Mode and Effects Analysis (HFMEA) is to:
- Assign blame for past adverse events
- Document incidents for insurance purposes
- Proactively identify and prevent potential process failures (Correct answer)
- Retrospectively analyze sentinel events
Correct answer: Proactively identify and prevent potential process failures
HFMEA is a prospective tool used to identify and mitigate potential failure points in healthcare processes before harm occurs.
Question 26: A risk manager notices that the hospital's general liability policy contains a 'subrogation waiver' clause for certain contractors. What does waiving subrogation mean?
- The insurer gives up its right to pursue a third party for reimbursement after paying a claim (Correct answer)
- The contractor's policy becomes primary over the hospital's policy
- The hospital agrees to defend the contractor in all lawsuits
- The insurer waives the deductible on the contractor's behalf
Correct answer: The insurer gives up its right to pursue a third party for reimbursement after paying a claim
Waiving subrogation means the insurer surrenders its legal right to recover from a responsible third party after indemnifying the insured, preventing it from suing the named contractor.
Question 27: A hospital's risk manager wants to identify risks related to medication reconciliation at discharge. Which method is MOST appropriate?
- Review of malpractice reserves
- Review of credentialing files
- Direct observation of the discharge process (Correct answer)
- Analysis of payer denials
Correct answer: Direct observation of the discharge process
Direct observation allows the risk manager to see the actual workflow and identify gaps or errors in the medication reconciliation process.
Question 28: Which approach best describes risk-based compliance management in the CPHRM field?
- Focusing only on past incidents
- Eliminating all possible risks
- Treating all risks equally
- Prioritizing resources based on risk severity and likelihood (Correct answer)
Correct answer: Prioritizing resources based on risk severity and likelihood
Risk-based compliance management involves assessing and prioritizing risks by their severity and likelihood to allocate resources effectively.
Question 29: Which governance body typically has ultimate oversight responsibility for an ERM program in a US hospital?
- The Quality Improvement Committee
- The Board of Directors (Correct answer)
- The Department of Health
- The Chief Medical Officer
Correct answer: The Board of Directors
The Board of Directors holds fiduciary and governance responsibility, including ultimate oversight of the organization's ERM program.
Question 30: What is the primary purpose of a root cause analysis (RCA) following an adverse event?
- To identify systemic factors contributing to the event and prevent recurrence (Correct answer)
- To assign blame to individual staff members
- To calculate the financial cost of the event
- To notify regulators of the incident
Correct answer: To identify systemic factors contributing to the event and prevent recurrence
RCA is a structured process focused on identifying underlying systemic causes rather than individual blame, enabling system-level improvements.
Question 31: What is the most important professional competency for CPHRM certification in loss prevention?
- Memorization of all reference materials
- Speed of task completion
- Ability to work alone exclusively
- Deep knowledge combined with practical application skills (Correct answer)
Correct answer: Deep knowledge combined with practical application skills
Professional competency requires both deep knowledge of the subject matter and the ability to apply that knowledge in practical situations.
Question 32: Which legal doctrine holds hospitals responsible for the negligent acts of their employed physicians?
- Contributory negligence
- Res ipsa loquitur
- Respondeat superior (Correct answer)
- Corporate negligence
Correct answer: Respondeat superior
Respondeat superior ('let the master answer') holds employers vicariously liable for the negligent acts of employees acting within the scope of their employment.
Question 33: A hospital settles a malpractice claim for $150,000. Under the National Practitioner Data Bank (NPDB) rules, this payment must be reported:
- Only when the physician is found liable by a court
- Within 30 days of the payment (Correct answer)
- At the hospital's discretion if the physician was not named
- Only if the payment exceeds $500,000
Correct answer: Within 30 days of the payment
NPDB regulations require that all medical malpractice payments made on behalf of a licensed healthcare practitioner be reported within 30 days.
Question 34: A 'never event' in healthcare quality improvement refers to:
- An event that is never reported to regulatory authorities
- Any event that rarely occurs in clinical practice
- A near-miss event with no patient harm
- A serious, largely preventable adverse event that should never occur (Correct answer)
Correct answer: A serious, largely preventable adverse event that should never occur
Never events are serious, preventable patient safety events that should not occur if evidence-based preventive measures are in place.
Question 35: Which accreditation body requires healthcare organizations to conduct a thorough and credible root cause analysis following a sentinel event?
- National Committee for Quality Assurance (NCQA)
- Centers for Medicare and Medicaid Services (CMS)
- Agency for Healthcare Research and Quality (AHRQ)
- The Joint Commission (TJC) (Correct answer)
Correct answer: The Joint Commission (TJC)
The Joint Commission requires organizations to perform a root cause analysis and develop an action plan after a sentinel event occurs.
Question 36: Which framework is most commonly referenced in healthcare enterprise risk management (ERM) programs in the US?
- PMBOK Guide
- COSO ERM Framework (Correct answer)
- Six Sigma DMAIC
- ISO 14001
Correct answer: COSO ERM Framework
The COSO ERM Framework is the most widely adopted standard for enterprise risk management in US healthcare organizations.
Question 37: A hospital uses ICD-10 coding data to identify high-risk diagnoses with elevated complication rates. This is an example of:
- Administrative data mining (Correct answer)
- Prospective risk identification
- Clinical benchmarking
- Concurrent review
Correct answer: Administrative data mining
Administrative data mining uses coded billing and clinical records to retrospectively identify patterns suggesting risk.
Question 38: Which financial metric best measures the adequacy of a self-insured healthcare organization's loss reserves relative to its exposure?
- Debt-service coverage ratio
- Loss development factor (LDF) (Correct answer)
- Reserve-to-payroll ratio
- Current ratio
Correct answer: Loss development factor (LDF)
The loss development factor (LDF) quantifies how much reported losses are expected to grow to their ultimate value, directly measuring reserve adequacy relative to future payments.
Question 39: The Anti-Kickback Statute prohibits knowingly and willfully offering, paying, soliciting, or receiving anything of value to induce or reward referrals of items or services covered by:
- Private commercial insurers only
- All payers including self-pay patients
- Federal healthcare programs such as Medicare and Medicaid (Correct answer)
- Out-of-network insurance plans
Correct answer: Federal healthcare programs such as Medicare and Medicaid
The Anti-Kickback Statute applies to Federal healthcare program business, primarily Medicare and Medicaid, and violations can result in criminal penalties and exclusion from federal programs.
Question 40: What is the function of a 'hammer clause' in a liability insurance policy?
- It authorizes the insurer to appoint defense counsel without consent
- It allows the insurer to limit its liability if the insured refuses a reasonable settlement (Correct answer)
- It requires the insured to pay defense costs upfront
- It mandates that all claims go to trial
Correct answer: It allows the insurer to limit its liability if the insured refuses a reasonable settlement
A hammer clause (or consent-to-settle clause) penalizes the insured by capping insurer liability at the rejected settlement amount if the insured refuses a reasonable offer.
Question 41: A 'never event' in the context of risk management and CMS policy refers to:
- A sentinel event requiring mandatory state reporting
- An event that must be immediately disclosed to The Joint Commission
- A serious, preventable adverse event for which CMS does not provide additional payment (Correct answer)
- An adverse event that occurs rarely but unpredictably
Correct answer: A serious, preventable adverse event for which CMS does not provide additional payment
CMS designates certain serious preventable adverse events as 'never events' (Hospital-Acquired Conditions) for which it will not provide additional reimbursement, incentivizing prevention.
Question 42: The 'Swiss Cheese Model' of accident causation is used in risk identification to illustrate that:
- Multiple system defenses must all fail simultaneously for harm to occur (Correct answer)
- A single failure is always sufficient to cause harm
- Human error is the primary cause of all adverse events
- Risk identification should focus only on frontline workers
Correct answer: Multiple system defenses must all fail simultaneously for harm to occur
The Swiss Cheese Model shows that harm results when holes (failures) in multiple defensive layers align, enabling a hazard to reach the patient.
Question 43: Which approach best describes risk-based compliance management in the CPHRM field?
- Treating all risks equally
- Eliminating all possible risks
- Prioritizing resources based on risk severity and likelihood (Correct answer)
- Focusing only on past incidents
Correct answer: Prioritizing resources based on risk severity and likelihood
Risk-based compliance management involves assessing and prioritizing risks by their severity and likelihood to allocate resources effectively.
Question 44: Which element is MOST critical to a valid informed consent process?
- Physician completion of the consent form
- A witness signature on the form
- Patient comprehension of material risks and alternatives (Correct answer)
- Administrative department approval
Correct answer: Patient comprehension of material risks and alternatives
Informed consent is valid only when the patient demonstrates understanding of the material risks, benefits, and alternatives to the proposed treatment.
Question 45: Which of the following BEST defines 'claims-made' insurance coverage?
- Coverage for incidents that occurred and are reported during the policy period (Correct answer)
- Coverage only for previously settled claims
- Coverage tied to the claimant's date of discovery
- Coverage for any claim regardless of when filed
Correct answer: Coverage for incidents that occurred and are reported during the policy period
A claims-made policy provides coverage only if the incident occurred and the claim is reported while the policy is in force.
Question 46: In the context of CPHRM, 'risk identification' in the emergency department most commonly involves which unique challenge?
- Identifying risks in a high-volume, high-acuity, time-pressured environment (Correct answer)
- Monitoring chronic disease management protocols
- Managing elective procedure scheduling
- Reviewing outpatient coding accuracy
Correct answer: Identifying risks in a high-volume, high-acuity, time-pressured environment
The ED's high volume, acuity, time pressure, and frequent handoffs create a uniquely complex risk environment requiring targeted identification strategies.
Question 47: Which accreditation standard requires hospitals to maintain a written policy for identifying and resolving conflicts of interest among leadership?
- HIPAA Security Rule administrative safeguards
- OSHA bloodborne pathogen standard
- CMS Conditions of Participation — Medical Staff
- Joint Commission Leadership standards (LD) (Correct answer)
Correct answer: Joint Commission Leadership standards (LD)
TJC Leadership chapter standards require organizations to have processes identifying and managing conflicts of interest among governing board members and executives.
Question 48: The Health Care Quality Improvement Act (HCQIA) of 1986 provides immunity to peer review participants primarily to:
- Protect patient records from subpoena
- Shield hospitals from malpractice liability
- Allow hospitals to deny staff privileges without explanation
- Encourage good-faith reporting and action against incompetent practitioners (Correct answer)
Correct answer: Encourage good-faith reporting and action against incompetent practitioners
HCQIA grants qualified immunity to peer review participants acting in good faith to encourage frank assessment of physician competence.
Question 49: What does 'failure mode and effects analysis' (FMEA) primarily help organizations accomplish?
- Analyze past claims for frequency
- Determine insurance premium rates
- Respond to regulatory citations
- Proactively identify and prioritize process vulnerabilities (Correct answer)
Correct answer: Proactively identify and prioritize process vulnerabilities
FMEA is a prospective risk assessment tool that identifies where and how a process might fail and ranks failure modes by risk priority.
Question 50: Which of the following best describes a 'risk trigger' in healthcare risk identification?
- A financial threshold that requires board notification
- An event that activates an insurance claim
- A mandatory report to a regulatory agency
- A data point or event that signals potential underlying risk (Correct answer)
Correct answer: A data point or event that signals potential underlying risk
Risk triggers are specific indicators or events that signal a potential problem warranting further investigation.
Question 51: A hospital's quality improvement team wants to test a small-scale change before full implementation. They should use which model?
- Lean value stream mapping
- Six Sigma DMAIC
- Plan-Do-Study-Act (PDSA) cycle (Correct answer)
- FMEA prospective analysis
Correct answer: Plan-Do-Study-Act (PDSA) cycle
The PDSA cycle is designed for small, rapid tests of change that allow teams to learn and refine interventions before broad implementation.
Question 52: A risk manager is evaluating the financial impact of retaining risk versus purchasing insurance. This analysis is BEST described as:
- Claims reserving
- Underwriting review
- Cost-benefit analysis of risk financing (Correct answer)
- Actuarial risk analysis
Correct answer: Cost-benefit analysis of risk financing
Comparing the costs of self-retention against insurance premiums and coverage is a cost-benefit analysis within risk financing decision-making.
Question 53: In risk analysis, 'residual risk' refers to:
- Risk deemed too minor to address
- Risk transferred to a third party
- Risk identified after a sentinel event
- Risk remaining after controls are applied (Correct answer)
Correct answer: Risk remaining after controls are applied
Residual risk is the level of risk that remains after all implemented risk controls have been applied and accepted.
Question 54: The primary purpose of a claims reserve is to:
- Pay defense attorney retainers
- Cover deductible payments
- Estimate the financial liability for pending claims (Correct answer)
- Fund patient compensation funds
Correct answer: Estimate the financial liability for pending claims
A claims reserve is a financial estimate set aside to cover the anticipated cost of settling or litigating a pending claim.
Question 55: Under HIPAA, protected health information (PHI) may be disclosed to a plaintiff's attorney in a malpractice case:
- At the discretion of the treating physician
- Freely, because litigation is a public matter
- Only after the case is settled
- Only with the patient's written authorization or a valid court order (Correct answer)
Correct answer: Only with the patient's written authorization or a valid court order
HIPAA requires either a valid patient authorization or a court order (such as a subpoena with proper notice) before PHI can be disclosed in litigation.
Question 56: A patient safety officer proposes adopting a 'just culture' model. This model primarily distinguishes between:
- Intentional harm and accidental harm for criminal prosecution
- Licensed and unlicensed personnel for disciplinary purposes
- Human error, at-risk behavior, and reckless behavior when determining accountability (Correct answer)
- Clinical and administrative staff in incident reporting
Correct answer: Human error, at-risk behavior, and reckless behavior when determining accountability
Just culture differentiates three behavioral categories—human error, at-risk behavior, and reckless behavior—to apply appropriate accountability and system responses.
Question 57: In CPHRM practice, what is the best approach to quality improvement in risk analysis?
- Use data-driven methods with measurable outcomes (Correct answer)
- Wait for problems to occur before acting
- Copy what other organizations do without analysis
- Make changes without measuring results
Correct answer: Use data-driven methods with measurable outcomes
Data-driven quality improvement with measurable outcomes ensures that changes actually produce the intended improvements and can be verified.
Question 58: An independent medical examination (IME) in a claims context is typically used to:
- Determine the treating physician's liability
- Establish the standard of care
- Obtain an objective assessment of the claimant's injuries and prognosis (Correct answer)
- Satisfy state licensing board requirements
Correct answer: Obtain an objective assessment of the claimant's injuries and prognosis
An IME provides an independent clinical opinion on the claimant's condition, causation, and future care needs to inform claims valuation.
Question 59: Which federal law prohibits healthcare providers from offering, paying, soliciting, or receiving anything of value to induce or reward referrals of federal healthcare program business?
- False Claims Act
- Stark Law
- Anti-Kickback Statute (Correct answer)
- Civil Monetary Penalties Law
Correct answer: Anti-Kickback Statute
The Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)) prohibits knowingly and willfully offering, paying, soliciting, or receiving remuneration to induce or reward referrals of items or services covered by federal healthcare programs.
Question 60: A risk manager evaluating the financial strength of a prospective insurer should PRIMARILY consult:
- The insurer's annual advertising budget
- The number of states in which the insurer is licensed
- AM Best, Moody's, or S&P financial strength ratings (Correct answer)
- The insurer's marketing brochures
Correct answer: AM Best, Moody's, or S&P financial strength ratings
AM Best, Moody's, and S&P provide independent financial strength ratings that assess an insurer's ability to meet its policyholder obligations—the most objective measure of solvency.
Question 61: A hospital implements a 'no-lift' policy for patient transfers. This is an example of which loss prevention strategy?
- Risk avoidance
- Risk transfer
- Risk reduction (Correct answer)
- Risk retention
Correct answer: Risk reduction
A no-lift policy reduces the frequency and severity of staff musculoskeletal injuries, making it a risk reduction strategy.
Question 62: Which of the following BEST represents an example of a 'process measure' in healthcare quality?
- Percentage of AMI patients receiving aspirin within 24 hours of arrival (Correct answer)
- Hospital-acquired Clostridioides difficile infection rate per 10,000 patient-days
- Average number of ICU beds per 1,000 admissions
- 30-day readmission rate following heart failure hospitalization
Correct answer: Percentage of AMI patients receiving aspirin within 24 hours of arrival
Process measures assess whether evidence-based care steps were performed, such as administering aspirin to AMI patients, which is a clinician action rather than an end result.
Question 63: During a risk analysis, a team determines that a control measure reduces the likelihood of a hazard but does not eliminate it. This remaining risk is BEST addressed by:
- Accepting the residual risk without further action if it falls below the risk tolerance threshold (Correct answer)
- Transferring full liability to the treating physician
- Reclassifying the hazard as a non-risk
- Removing the control and escalating to senior leadership
Correct answer: Accepting the residual risk without further action if it falls below the risk tolerance threshold
When residual risk falls within the organization's defined risk tolerance, it is appropriate to formally accept it and document the decision.
Question 64: In conducting a Failure Mode and Effects Analysis (FMEA), the Risk Priority Number (RPN) is calculated by multiplying:
- Frequency Ă— Detectability Ă— Controllability
- Severity Ă— Occurrence Ă— Detection (Correct answer)
- Probability Ă— Harm Ă— Reversibility
- Likelihood Ă— Impact Ă— Cost
Correct answer: Severity Ă— Occurrence Ă— Detection
RPN = Severity × Occurrence × Detection, with each factor typically scored 1–10, producing scores from 1 to 1,000.
Question 65: A hospital risk manager is asked to justify the return on investment (ROI) of the risk management program. Which metric would BEST demonstrate financial value?
- The size of the risk management department's budget
- Total number of claims filed annually
- Reduction in total cost of risk year-over-year relative to program expenditures (Correct answer)
- The number of safety training sessions conducted
Correct answer: Reduction in total cost of risk year-over-year relative to program expenditures
ROI is best demonstrated by showing that reductions in total cost of risk (losses, premiums, expenses) exceed the cost of the risk management program itself.
Question 66: In CPHRM practice, what is the primary purpose of strategic planning?
- To satisfy external auditors
- To create paperwork
- To align resources with goals and anticipate challenges (Correct answer)
- To reduce workforce
Correct answer: To align resources with goals and anticipate challenges
Strategic planning aligns organizational resources with goals and helps anticipate challenges before they become critical issues.
Question 67: What is the most important professional competency for CPHRM certification in quality improvement?
- Speed of task completion
- Memorization of all reference materials
- Deep knowledge combined with practical application skills (Correct answer)
- Ability to work alone exclusively
Correct answer: Deep knowledge combined with practical application skills
Professional competency requires both deep knowledge of the subject matter and the ability to apply that knowledge in practical situations.
Question 68: A patient refuses a recommended procedure. Which action BEST protects the organization from future liability?
- Document the informed refusal with the patient's stated reasons (Correct answer)
- Consult only the attending physician
- Proceed with the procedure anyway
- Discharge the patient immediately
Correct answer: Document the informed refusal with the patient's stated reasons
Documenting informed refusal, including the risks explained and the patient's stated reasons, demonstrates respect for autonomy and reduces liability.
Question 69: Which approach best demonstrates mastery of risk identification in CPHRM practice?
- Relying entirely on technology
- Applying principles to novel situations with sound judgment (Correct answer)
- Following procedures without understanding
- Avoiding complex scenarios
Correct answer: Applying principles to novel situations with sound judgment
True mastery involves understanding underlying principles well enough to apply them to new and unfamiliar situations with professional judgment.
Question 70: In CPHRM practice, what is the best approach to quality improvement in loss prevention?
- Wait for problems to occur before acting
- Make changes without measuring results
- Use data-driven methods with measurable outcomes (Correct answer)
- Copy what other organizations do without analysis
Correct answer: Use data-driven methods with measurable outcomes
Data-driven quality improvement with measurable outcomes ensures that changes actually produce the intended improvements and can be verified.
Question 71: Which federal regulation requires hospitals to have an infection control committee and a designated infection control officer?
- CMS Conditions of Participation §482.42 (Correct answer)
- CDC Healthcare Infection Control Practices Advisory Committee guidelines
- The Joint Commission Infection Prevention Standards
- OSHA Bloodborne Pathogens Standard
Correct answer: CMS Conditions of Participation §482.42
CMS CoPs at §482.42 require hospitals to have an active program for the prevention, control, and investigation of infections and communicable diseases, including qualified personnel and oversight.
Question 72: When analyzing a medication error involving a look-alike/sound-alike drug, the quality improvement team should focus PRIMARILY on:
- Educating nurses on proper drug identification techniques
- Removing the drug from the formulary permanently
- Disciplining the pharmacist who dispensed the medication
- Redesigning the system to prevent future errors of the same type (Correct answer)
Correct answer: Redesigning the system to prevent future errors of the same type
A systems approach recognizes that errors result from system failures rather than individual negligence, and focuses on redesigning processes to make errors less likely.
Question 73: A hospital's risk manager is evaluating a clinical process with multiple sequential steps, each with its own failure probability. Which method is BEST suited to calculate the probability that the entire process fails?
- Root cause analysis
- FMEA severity scoring
- Fault tree analysis (Correct answer)
- Pareto analysis
Correct answer: Fault tree analysis
Fault tree analysis uses Boolean logic gates to model how combinations of individual failures lead to a top-level undesired event.
Question 74: Which component of the risk management process involves assigning likelihood and impact scores to identified risks?
- Risk monitoring
- Risk treatment
- Risk analysis (Correct answer)
- Risk identification
Correct answer: Risk analysis
Risk analysis evaluates identified risks by estimating their probability and potential severity of impact, often producing a risk score or rating.
Question 75: An advance directive executed in one state by a patient who is now hospitalized in a different state is:
- Only valid if notarized in the patient's home state
- Invalid unless approved by the hospital ethics committee
- Automatically invalid and must be re-executed in the current state
- Generally honored under most states' reciprocity provisions, though state law varies (Correct answer)
Correct answer: Generally honored under most states' reciprocity provisions, though state law varies
Most states have provisions to honor out-of-state advance directives to the extent they comply with the originating state's law, though risk managers should know their specific state's rules.
Question 76: A hospital compliance officer discovers that a vendor is offering free meals to physicians who refer patients to their durable medical equipment company. This arrangement most likely violates:
- The Anti-Kickback Statute only (Correct answer)
- HIPAA's privacy regulations
- Both the Stark Law and the Anti-Kickback Statute
- The Stark Law only
Correct answer: The Anti-Kickback Statute only
While the Stark Law applies to physician referrals for designated health services to entities with a financial relationship, the Anti-Kickback Statute more broadly applies to any remuneration intended to induce referrals for federal healthcare program items, including DME.
Question 77: A risk manager applies a 'bow-tie' model to a medication error risk. The LEFT side of the bow-tie represents:
- Consequences and recovery controls
- Corrective actions taken after an incident
- Threats and preventive barriers leading to the hazardous event (Correct answer)
- Regulatory penalties associated with the risk
Correct answer: Threats and preventive barriers leading to the hazardous event
The left side of a bow-tie diagram maps threats (causes) and preventive controls that reduce the likelihood of the central hazardous event.
Question 78: Which risk financing option provides the greatest potential cost savings to a healthcare organization with consistently favorable loss experience?
- Self-insurance with a funded reserve (Correct answer)
- Occurrence-based commercial insurance
- Guaranteed-cost insurance
- Finite risk insurance
Correct answer: Self-insurance with a funded reserve
Self-insurance allows organizations with low and predictable losses to retain premium savings rather than paying fixed commercial premiums that include insurer profit and overhead.
Question 79: Environmental rounds conducted by risk management primarily help to identify which type of risk?
- Physical hazard risks (Correct answer)
- Financial risks
- Compliance risks
- Reputational risks
Correct answer: Physical hazard risks
Environmental rounds involve walking through facilities to identify physical hazards such as slip/trip hazards, unsafe equipment, or fire risks.
Question 80: Which legal theory holds a hospital liable for negligent acts of independent contractor physicians based on the patient's reasonable belief that the physician was a hospital employee?
- Respondeat superior
- Vicarious liability
- Corporate negligence
- Ostensible agency (apparent authority) (Correct answer)
Correct answer: Ostensible agency (apparent authority)
Ostensible agency holds hospitals liable when patients reasonably believe an independent contractor physician is a hospital employee, typically due to hospital representations.
Question 81: In quality improvement, a 'tracer methodology' used by The Joint Commission involves:
- Tracing the source of a healthcare-associated infection outbreak
- Following a patient's care experience through the organization to evaluate system performance (Correct answer)
- Tracking financial costs of adverse events across departments
- Monitoring staff compliance with hand hygiene protocols via observation
Correct answer: Following a patient's care experience through the organization to evaluate system performance
Tracer methodology follows an individual patient's care journey through the organization to evaluate actual compliance with standards and identify system gaps.
Question 82: A hospital experiences a ransomware attack that encrypts patient records. This event is primarily categorized as which type of operational risk?
- Cybersecurity / information technology risk (Correct answer)
- Environmental health risk
- Clinical liability risk
- Workers' compensation risk
Correct answer: Cybersecurity / information technology risk
Ransomware attacks targeting patient records are a cybersecurity operational risk that can disrupt care delivery and compromise protected health information.
Question 83: A risk manager wants to identify safety risks in the sterile processing department. Which tool would be MOST appropriate?
- Structured process observation and FMEA (Correct answer)
- Analysis of malpractice claims from last year
- Patient satisfaction surveys
- Staff credentialing file review
Correct answer: Structured process observation and FMEA
Structured process observation combined with FMEA allows systematic prospective identification of contamination or sterilization failure risks.
Question 84: A risk manager identifies a risk with high severity but very low probability. According to standard risk matrix principles, this risk would MOST likely be categorized as:
- Transferred risk suitable for insurance only
- Moderate to high priority requiring monitoring and contingency planning (Correct answer)
- Acceptable risk needing no further action
- Low priority — probability outweighs severity
Correct answer: Moderate to high priority requiring monitoring and contingency planning
High-severity, low-probability risks typically fall into a moderate-to-high zone requiring contingency plans because consequences would be catastrophic if realized.
Question 85: In the context of healthcare litigation, 'discovery' refers to:
- A physician's duty to disclose diagnoses to patients
- A hospital's internal incident investigation
- The risk manager's root cause analysis
- The pre-trial process of obtaining evidence from the opposing party (Correct answer)
Correct answer: The pre-trial process of obtaining evidence from the opposing party
Discovery is the pre-trial legal process through which parties exchange information and evidence, including depositions, interrogatories, and document requests.
Question 86: A risk manager is reviewing compliance with the Patient Self-Determination Act (PSDA). The PSDA requires hospitals to:
- Inform patients of their right to make advance directives upon admission (Correct answer)
- Ensure all patients have completed a living will before elective procedures
- Appoint a patient advocate for every admitted patient
- Obtain informed consent for all procedures regardless of urgency
Correct answer: Inform patients of their right to make advance directives upon admission
The PSDA requires Medicare and Medicaid participating providers to inform adult patients of their rights under state law to make advance directives and to document whether they have one.
Question 87: A 'near miss' event in patient safety is BEST defined as:
- An event that caused minor harm requiring no treatment
- An error that was caught and corrected before reaching the patient (Correct answer)
- An event that caused significant harm to a patient
- An event that reached the patient but caused no harm
Correct answer: An error that was caught and corrected before reaching the patient
A near miss is an unsafe condition or unplanned event that did not reach the patient but had the potential to cause harm if not intercepted.
Question 88: Under the Emergency Medical Treatment and Labor Act (EMTALA), a hospital with an emergency department must:
- Obtain a deposit before performing a medical screening exam
- Provide a medical screening examination to anyone who presents regardless of ability to pay (Correct answer)
- Notify the patient's insurer before initiating emergency treatment
- Transfer all uninsured patients to public hospitals immediately
Correct answer: Provide a medical screening examination to anyone who presents regardless of ability to pay
EMTALA mandates that covered hospitals provide a medical screening examination to all individuals presenting to the ED regardless of their financial status.
Question 89: What role does documentation play in CPHRM compliance?
- It replaces practical competency
- It provides evidence of adherence to standards (Correct answer)
- It is only needed for audits
- It is optional
Correct answer: It provides evidence of adherence to standards
Documentation provides verifiable evidence that standards and regulations are being followed, serving as proof of compliance.
Question 90: A healthcare organization benchmarks its claim frequency against national data. This activity is part of which risk management function?
- Risk transfer
- Risk financing
- Risk control
- Risk identification and analysis (Correct answer)
Correct answer: Risk identification and analysis
Comparing internal claims data to external benchmarks is a risk identification and analysis activity that reveals relative performance and areas for improvement.
Question 91: When a risk manager conducts a 'mock trial' or focus group before a case goes to trial, the PRIMARY goal is to:
- Identify expert witnesses for the defense
- Practice witness examination techniques
- Train new risk management staff on courtroom procedures
- Assess how jurors might perceive the case and evaluate settlement value (Correct answer)
Correct answer: Assess how jurors might perceive the case and evaluate settlement value
Mock trials and focus groups help predict juror reactions to the evidence and arguments, informing settlement decisions and trial strategy.
Question 92: Which of the following conditions would NOT fall under the Emergency Medical Treatment and Active Labor Act's definition of an emergency?
- Kidney failure
- Raptured appendix
- Normal child labor (Correct answer)
- Myocardial infarction
Correct answer: Normal child labor
EMTALA defines an 'emergency medical condition' as one that could reasonably be expected to result in serious jeopardy to health, serious impairment to bodily functions, or serious dysfunction of any bodily organ. While active labor is covered, 'normal child labor' implies a routine, uncomplicated delivery that does not present an immediate threat to the mother or baby once stabilized. Conditions like ruptured appendix, kidney failure, and myocardial infarction clearly meet the definition of an emergency requiring immediate stabilizing treatment.
Question 93: A hospital risk manager is comparing 'funded' vs. 'unfunded' retention strategies. The primary financial risk of an unfunded retention program is:
- Unfunded programs require a higher level of reinsurance
- Unexpected large losses must be absorbed from operating revenue, potentially destabilizing cash flow (Correct answer)
- Overfunding creates excess capital that cannot be invested
- Funded programs generate taxable investment income
Correct answer: Unexpected large losses must be absorbed from operating revenue, potentially destabilizing cash flow
Without pre-funded reserves, an unexpected large retained loss must be paid directly from operating funds, which can disrupt cash flow and operational stability.
Question 94: Which of the following best describes the purpose of credentialing and privileging in reducing operational risk?
- To reduce the number of physicians on staff
- To verify that providers have the competence to perform specific procedures safely (Correct answer)
- To negotiate lower malpractice insurance rates
- To satisfy Joint Commission administrative requirements only
Correct answer: To verify that providers have the competence to perform specific procedures safely
Credentialing and privileging verify provider qualifications and competency, directly reducing the risk of harm from unqualified practitioners.
Question 95: Which concept in risk analysis refers to defenses, barriers, and safeguards that, when all have gaps simultaneously, allow an adverse event to occur?
- Bow-tie model
- Domino theory
- Swiss cheese model (Correct answer)
- Haddon matrix
Correct answer: Swiss cheese model
The Swiss cheese model (Reason's model) illustrates how latent and active failures in multiple system layers must align for an accident to happen.
Question 96: In a healthcare ERM program, 'strategic risk' most likely includes which of the following?
- A nurse's failure to follow hand hygiene protocol
- A billing error on a single claim
- A slip-and-fall incident in the cafeteria
- A competitor opening a new facility in the service area (Correct answer)
Correct answer: A competitor opening a new facility in the service area
Strategic risk involves threats to an organization's ability to achieve its long-term goals, such as competitive market changes.
Question 97: Which of the following is an example of a structure measure in healthcare quality?
- Percentage of patients receiving discharge education
- Patient mortality rate
- Average length of hospital stay
- Nurse-to-patient staffing ratio (Correct answer)
Correct answer: Nurse-to-patient staffing ratio
Structure measures assess organizational attributes like staffing ratios, equipment, and facilities rather than processes or outcomes.
Question 98: What are the four elements of the situational briefing model called the SBAR?
- Scenario, basis, acquisition, and response
- Status, briefing, analysis, and reconnaissance
- Situation, background, assessment, and recommendation (Correct answer)
- Safety, bearing, argument, and rationale
Correct answer: Situation, background, assessment, and recommendation
SBAR is a standardized communication tool widely adopted in healthcare to improve the clarity and efficiency of information exchange, especially during critical situations or handoffs. The acronym stands for Situation, Background, Assessment, and Recommendation. This structured approach ensures that all essential patient information is conveyed concisely and logically, promoting patient safety and effective decision-making among healthcare professionals.
Question 99: Which metric is MOST useful for evaluating the effectiveness of a healthcare organization's claims management program over time?
- Number of claims filed per year
- Number of incident reports submitted
- Total litigation hours logged by defense counsel
- Average claim cost and closure rate trends (Correct answer)
Correct answer: Average claim cost and closure rate trends
Tracking average claim cost and closure rate trends reveals whether claims are being resolved efficiently and at lower financial impact over time.
Question 100: The principle of 'insurable interest' requires that for an insurance contract to be valid:
- The policy must cover at least three separate risk categories
- The insured must be a licensed healthcare provider
- The insured must suffer a financial loss if the insured event occurs (Correct answer)
- The insurer must be domiciled in the same state as the insured
Correct answer: The insured must suffer a financial loss if the insured event occurs
Insurable interest means the policyholder must stand to suffer a genuine financial loss from the event insured against, preventing insurance from becoming a wagering instrument.
Question 101: Which of the following BEST describes the purpose of a 'heat map' in risk analysis?
- To track temperature-related environmental hazards
- To map staff workload density across departments
- To visualize geographic distribution of patient falls
- To display the aggregated risk scores of identified risks on a color-coded matrix (Correct answer)
Correct answer: To display the aggregated risk scores of identified risks on a color-coded matrix
A heat map plots risks on a likelihood-vs.-consequence matrix using color coding (green/yellow/red) to allow quick visual prioritization.
Question 102: What role does collaboration play in quality improvement for CPHRM professionals?
- It is only needed in emergencies
- It slows down work unnecessarily
- It enhances outcomes through diverse perspectives and shared expertise (Correct answer)
- It reduces individual accountability
Correct answer: It enhances outcomes through diverse perspectives and shared expertise
Collaboration leverages diverse perspectives and combined expertise to achieve better outcomes than any individual could alone.
Question 103: Under the Americans with Disabilities Act (ADA), a hospital's obligation to a qualified individual with a disability includes:
- Exemption from standard informed consent procedures
- Making reasonable accommodations unless they impose an undue hardship (Correct answer)
- Assigning a dedicated care team to all patients with disabilities
- Providing any accommodation the patient requests regardless of cost
Correct answer: Making reasonable accommodations unless they impose an undue hardship
The ADA requires reasonable accommodations for individuals with disabilities, but not accommodations that would impose an undue hardship on the organization.
Question 104: Which risk financing strategy requires the healthcare organization to retain all financial risk for claims below a set dollar threshold?
- Self-insured retention (SIR) (Correct answer)
- Captive insurance
- Umbrella coverage
- Occurrence-based insurance
Correct answer: Self-insured retention (SIR)
A self-insured retention (SIR) requires the insured organization to pay all costs — including defense and indemnity — for claims up to the retention amount before insurance responds.
Question 105: Under EMTALA, a hospital's obligation to provide an appropriate medical screening examination applies to:
- Only patients with Medicare or Medicaid insurance
- Any individual who comes to the emergency department requesting examination or treatment (Correct answer)
- Only patients who are transported by ambulance
- Patients who present with life-threatening conditions only
Correct answer: Any individual who comes to the emergency department requesting examination or treatment
EMTALA applies to any individual who comes to a hospital emergency department and requests examination or treatment for a medical condition, regardless of ability to pay or insurance status.
Question 106: The 'locality rule' in medical malpractice standards of care has largely been replaced by:
- A state-by-state statutory standard
- The CMS Conditions of Participation standard
- A national standard of care reflecting what a reasonably competent physician would do (Correct answer)
- An evidence-based standard set by specialty boards
Correct answer: A national standard of care reflecting what a reasonably competent physician would do
Modern malpractice law generally applies a national standard of care — what a reasonably competent physician in the same specialty would do — rather than the outdated locality-based standard.
Question 107: An insurance policy's 'insuring agreement' is BEST described as:
- The schedule of covered locations and property values
- The core promise by the insurer to pay covered losses in exchange for premium (Correct answer)
- The conditions the insured must meet to maintain coverage
- The section listing all exclusions from coverage
Correct answer: The core promise by the insurer to pay covered losses in exchange for premium
The insuring agreement is the heart of the policy—it defines the insurer's fundamental promise to pay, defend, or indemnify for covered claims.
Question 108: What is the most important professional competency for CPHRM certification in insurance and finance?
- Ability to work alone exclusively
- Speed of task completion
- Deep knowledge combined with practical application skills (Correct answer)
- Memorization of all reference materials
Correct answer: Deep knowledge combined with practical application skills
Professional competency requires both deep knowledge of the subject matter and the ability to apply that knowledge in practical situations.
Question 109: In the CPHRM field, what does the duty of competence require?
- Avoiding difficult cases
- Maintaining current knowledge and skills within one's scope (Correct answer)
- Working beyond one's training
- Knowing everything
Correct answer: Maintaining current knowledge and skills within one's scope
The duty of competence requires practitioners to maintain current knowledge and skills, and to work within the boundaries of their training and expertise.
Question 110: A risk manager is analyzing claims data to identify patterns of recurring loss. Which type of analysis is being performed?
- Retrospective risk analysis (Correct answer)
- Predictive modeling
- Concurrent risk analysis
- Prospective risk analysis
Correct answer: Retrospective risk analysis
Retrospective risk analysis examines historical data (claims, incidents, near-misses) to identify patterns and trends of past losses.
ASHRM Certified Professional in Healthcare Risk Management (CPHRM) Exam
The ASHRM CPHRM exam certifies healthcare risk management professionals in risk identification, risk analysis, loss prevention, claims management, patient safety, regulatory compliance, quality improvement, insurance and finance, legal issues, and enterprise risk management.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds